Click to See Complete Forum and Search --> : suspicious saslauthd activity
kidsleep
09-12-2003, 02:19 PM
I left my machine on all night last night and left myself logged on. When I awoke this morning I found that it was at the login screen. I ran drakconf and found some activity between 4-5am attached is a text file with only the activity between that time. I'm not familiar with saslauthd and this may all be harmless, but I've gotta know. Anything I need to worry about? Have I been hacked?
TIA
kshim5
09-12-2003, 02:31 PM
This looks like updates that were made to your system lately.
kidsleep
09-12-2003, 03:26 PM
kshim5, I saw that as well. I'm not yet experienced enough to know what the files were though. What gets me though is how they got in. My firewall rules are pretty fierce; they block all syn packets and I don't have anything running but the X11 port 6000. I ran nmap and confirmed this only a few minutes ago. I thought about running snort but haven't done so yet. I guess now is as good a time as any. Thanks
kshim5
09-12-2003, 03:48 PM
Check the dates that are printed in the file to see if they coinside with the dates that you updated your system.
kidsleep
09-15-2003, 01:50 PM
Thanks man! I think that is what it was.